Back

HIGH

kernel: Integer overflow in snd_compr_allocate_buffer()

Published Jun 27, 2016

Description

The snd_compress_check_input function in sound/core/compress_offload.c in the ALSA subsystem in the Linux kernel before 3.17 does not properly check for an integer overflow, which allows local users to cause a denial of service (insufficient memory allocation) or possibly have unspecified other impact via a crafted SNDRV_COMPRESS_SET_PARAMS ioctl call.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner google_android
Published Jun 27, 2016
Updated Aug 6, 2024
Reserved Jun 24, 2016
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 16, 2014